BNM RMiT Compliance Training (Risk Management in Technology)

A one-day programme on Bank Negara Malaysia's Risk Management in Technology (RMiT) policy document, for staff at licensed banks, Islamic banks, investment banks, insurers and takaful operators, development financial institutions, electronic money issuers and payment system operators. RMiT is a supervisory expectation with teeth: it names the governance structures that must exist, the control standards technology must meet, the testing that must be performed, and the events that must be reported to the Bank within 24 hours.

The programme works through those requirements as an internal compliance exercise rather than a reading of the policy document. Participants finish by scoring their own institution against the control domains covered and identifying where the evidence for compliance does not yet exist. Content can be tailored to the institution's licence category and to the audience's mix of technology, risk and audit roles.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

9:15 AM - 10:15 AM

RMiT: Scope, Structure and Supervisory Expectations

Which institutions RMiT applies to and how it relates to the Bank's other policy documents on outsourcing, business continuity and operational risk. How RMiT compliance is examined in practice, the difference between a standard and a guidance paragraph, and what supervisors typically ask for first.

03

10:15 AM - 11:15 AM

Governance and Oversight

Board and senior management responsibilities, the Technology Risk Management Framework and the Cyber Resilience Framework, the role and independence of the Chief Information Security Officer, the three lines of defence applied to technology risk, and the technology risk appetite statement and how it is meant to bite on real decisions.

04

11:15 AM - 11:30 AM

Break

05

11:30 AM - 12:30 PM

Technology Operations and Resilience

Data centre and network resilience, capacity management, change and patch management, the availability expectation for critical systems and the associated unscheduled downtime reporting duty, recovery time and recovery point objectives, and disaster recovery testing that produces usable evidence.

06

12:30 PM - 1:30 PM

Lunch

07

1:30 PM - 2:30 PM

Cyber Security Controls

Access control and privileged access management, cryptography and key management, the security operations centre, threat intelligence and industry information sharing, vulnerability management, penetration testing and adversarial attack simulation, and the heightened control expectations for internet-facing and customer-facing systems.

08

2:30 PM - 3:15 PM

Cloud, Third Parties and Outsourcing

Supervisory expectations before adopting cloud services for critical systems, the risk assessment and prior engagement with the Bank, concentration risk, exit strategy and portability, and the contractual, access and audit rights an institution needs over its technology service providers.

09

3:15 PM - 3:30 PM

Break

10

3:30 PM - 4:15 PM

Incident Management and Reporting to the Bank

Classification of technology and cyber incidents, the 24-hour notification duty, the content of the initial notification and of the follow-up report, coordination between the security operations centre, business continuity and communications, and the post-incident review the Bank will expect to see.

11

4:15 PM - 4:45 PM

Self-Assessment Workshop

Participants score their own institution against the RMiT control domains covered during the day, identify the three weakest, and assign owners.

12

4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Intermediate, suitable for IT, information security, technology risk, operational risk, compliance and internal audit staff at BNM-regulated institutions

Duration   1 Day (8 Hours)  |  9:00 AM to 5:00 PM

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   10 to 15 question knowledge assessment covering all modules

Certificate   Certificate of Completion issued to all participants upon full attendance

EnquiriesContact us to register or discuss scheduling